Uncover Hidden Lease Components in Software Agreements
For a complete breakdown, see our ASC 842 compliance guide.
Embedded leases in IT and software contracts are a lasting challenge under ASC 842 for controllers, accounting managers, and auditors. This area of lease accounting often trips up even seasoned professionals. Many organizations zero in on explicit lease agreements. They often miss embedded leases within broader service or technology contracts.
The audit and compliance risk from an incomplete lease population is large. It can lead to material misstatements and costly restatements. ASC 842 audit procedures target the completeness assertion for leases. That means a team must carefully identify all agreements that grant control over an identified asset for a period.
Q: What constitutes a hidden lease component in IT and software contracts? A: In an IT contract, a hidden lease component arises when a customer obtains the right to control the use of identified property, plant or equipment for a period. Think dedicated servers, network hardware, a fiber-optic line, data-center space, or devices. That holds even if the contract is couched as a service agreement.
The software itself is never that asset. ASC 842-10-15-1(a) excludes leases of intangible assets from Topic 842 and sends them to Topic 350, as Deloitte's Roadmap: Leases, Chapter 2 sets out. So a software license, a named software instance and a cloud subscription are evaluated under ASC 350-40, not ASC 842. What you are hunting for in a software contract is the hardware and space underneath it.
This differs quite a bit from overt leases for traditional assets like real estate or vehicles. The label on the contract decides nothing. Under ASC 842-10-15-3, a contract is or contains a lease if it conveys the right to control the use of identified property, plant or equipment. That right must run for a period of time and be exchanged for consideration.
An arrangement carrying the right to use an identified asset "may appear to be a supply arrangement or service contract," as PwC's Leases guide puts it. So a document titled "Master Services Agreement" contains a lease to the extent it meets that definition. Under the ASC 842 glossary, a right-of-use (ROU) asset is an asset that represents a lessee's right to use an underlying asset for the lease term.
What Auditors Look For in IT and Software Contracts
Auditors perform rigorous lease audit procedures to make sure an organization's lease population is complete. Their main focus is always the completeness assertion for leases. They verify that the entity has identified and properly recorded all qualifying lease arrangements, including embedded leases. Auditors usually do this by looking at the process an entity uses to identify leases, looking for systemic gaps, and performing substantive tests on a sample of contracts.
✅ Best Practice: Companies with strong internal controls for lease identification often bring cross-functional teams into contract review, including IT, procurement, and legal. This joint approach greatly reduces the risk of overlooking embedded leases. It pays off during every audit cycle.
Auditors check whether the entity's policy for identifying leases is adequate. Just as important, they check whether internal controls over this process are effective. This includes reviewing vendor contracts, especially those over certain dollar thresholds or with long-term commitments for IT infrastructure.
They look for evidence that management took proactive steps to identify hidden lease components, not just explicit lease agreements. Deloitte's lease-standard FAQs flag where this assessment gets hard. Cloud computing arrangements are on that list, where the question is whether there is "a lease of the supporting equipment, such as mainframes and servers."1
| Audit Focus Area | Auditor's Objective | Key Evidence Sought |
|---|---|---|
| Completeness | Ensure all contracts meeting the definition of a lease are identified and recorded. | Documented lease identification policy, contract review logs, completeness testing of contract population. |
| Existence | Verify identified leases are valid and represent actual rights and obligations. | Executed contracts, payment schedules, asset identification. |
| Rights & Obligations | Confirm the entity has the right to use the asset and an obligation to pay. | Contract terms outlining control criteria and payment commitments. |
| Valuation | Assess accuracy of ROU asset and lease liability measurements. | Present value calculations, discount rate determination, lease term analysis. |
| Presentation & Disclosure | Verify compliance with ASC 842 disclosure requirements. | Financial statement footnotes, supporting schedules. |
Auditors apply lease identification audit techniques to check contracts for specific traits that indicate a lease. To do this, they need to understand how an organization's teams buy IT assets and services. The more complex the IT architecture, the higher the risk of an incomplete lease population because of missed embedded leases.
Auditors will often ask IT and procurement staff directly about the nature of their service agreements and how they use assets. They refer to general guidance on ASC 842, available through resources like the ASC 842 pre-audit self-assessment.
Where Software Contracts Hide Lease Components
A company that fails to properly identify and account for embedded leases in IT and software contracts faces serious financial reporting and compliance risks. Misclassification can lead to understated lease liabilities and ROU assets. That affects key financial ratios and compliance with debt covenants. This pattern shows up in practice.
- Understated Lease Liabilities and ROU Assets: When a company overlooks embedded leases, it leaves obligations and the related assets off the balance sheet. This directly misrepresents the entity's financial position and affects solvency and liquidity metrics.
- Inaccurate Financial Ratios: An incomplete lease population can distort key financial ratios such as debt-to-equity, current ratio, and return on assets. Investors, lenders, and other stakeholders rely on these ratios to make decisions.
- Non-Compliance with ASC 842: Non-compliance can lead to audit qualifications and restatements. For a public company it can also draw regulatory scrutiny from the Securities and Exchange Commission.
- Challenges with Future Lease Management: A partial lease population makes future lease administration harder, including renewals, modifications, and terminations.
- Ineffective Internal Controls: A weak process for finding embedded leases points to a deficiency in internal control over financial reporting. If the auditor concludes it rises to a significant deficiency or a material weakness, that gets communicated in writing to those charged with governance. The severity assessment, not the existence of the gap, decides whether the audit committee hears about it.2
⚠️ Risk Alert: A common audit finding, especially at technology-heavy companies, involves overlooked service contracts for outsourced IT infrastructure. Control is the hinge, and it is never implied by dedication: read who decides how and for what purpose each server is used (ASC 842-10-15-4). Where the customer makes those decisions, there is a lease and the ROU asset audit is affected.
Example Scenario: Imagine a mid-sized manufacturing company that signs a five-year contract with a cloud service provider. The contract covers dedicated servers to host the company's proprietary enterprise resource planning (ERP) system. It specifies the exact servers (by serial number) the manufacturer will use and grants the manufacturer the right to dictate how these servers are configured and used. The provider services and maintains the hardware.
The contract is termed a "service agreement," yet the manufacturer controls an identified asset (the specified servers) for a period. If the accounting team fails to identify this as an embedded lease, both the ROU asset and lease liability will be left off the balance sheet. That leads to a misstatement under ASC 842. This is a classic "hidden lease" situation.
Change one fact and the answer changes. In the FASB's Example 10, Case A, the supplier installs and configures servers at the customer's premises and decides how they are configured and used. That contract is a service contract and contains no lease (ASC 842-10-55-124 through 55-126). Case B is this scenario: an identified server the customer configures and integrates, which does contain a lease (ASC 842-10-55-127 through 55-130).
Practical Checklist for Embedded Lease Discovery
An embedded lease refers to a lease component inside a larger contract that may not be explicitly identified as a lease. Finding these in IT and software contracts takes a systematic review. The checklist below supports the embedded lease discovery process and helps with identifying embedded leases in contracts.
| Checklist Item | Key Review Point | What to Look For |
|---|---|---|
| 1. Identify IT & Software Contracts | Compile a comprehensive list of all IT-related agreements. | Service agreements, outsourcing contracts, cloud agreements (Infrastructure as a Service, or IaaS; Platform as a Service, or PaaS), hardware leases, software licenses, network infrastructure deals. Review software licenses and cloud subscriptions too, then route them out to Topic 350 (ASC 842-10-15-1(a)); what you keep from them is any hardware or space they carry. |
| 2. "Identified Asset" Test | Does the contract specify a particular asset? | Serial numbers, specific server racks, dedicated fiber optic lines, named data-center cabinets or cages. Not the software itself: ASC 842-10-15-1(a) puts leases of intangible assets in Topic 350. |
| 3. "Right to Control Use" Test | Does the customer have control over how the asset is used (ASC 842-10-15-4)? | Both limbs must hold: the customer directs the use of the asset, and obtains substantially all the economic benefits from its use. |
| 4. Supplier Substitution Rights | Does the supplier have both the practical ability to substitute an alternative asset throughout the period of use and an economic benefit from doing so (ASC 842-10-15-10)? | Both limbs must hold, or the right is not substantive and there is still an identified asset. Weigh the supplier's cost of moving and re-provisioning the asset against what it gains. |
| 5. Lease Term Determination | What is the non-cancellable period of use? | Initial contract period, renewal options that are reasonably certain to be exercised (ASC 842-10-30-1). |
| 6. Consideration Allocation | Can the lease component be segregated from service components? | Look for explicit pricing for hardware vs. services, or use observable standalone prices (ASC 842-10-15-33). |
| 7. Contractual Clauses Review | Review specific sections for lease indicators. | Rights to change asset configuration, dedicated use clauses, penalty for early termination, clauses about asset location/maintenance. |
| 8. Periodic Re-evaluation | Establish regular review cycles for new and existing contracts. | Set up processes for triggering a lease assessment when new contracts are signed or existing ones are modified. |
Three details settle most substitution questions. An asset sitting at your own premises generally costs more to swap, so substitution is less likely to pay for the supplier (ASC 842-10-15-12). A right to substitute only for repairs, maintenance or a technical upgrade does not stop the asset being identified (ASC 842-10-15-14). If you cannot readily tell whether a substitution right is substantive, presume it is not (ASC 842-10-15-15).
This checklist matches our general guidance on lease completeness under ASC 842. It gives a base for a thorough contract review. Your organization's ASC 842 management assertions can also give more guidance on these tests.
How to Evidence Your IT Contract Review
To validate your lease identification approach, combine internal controls, expert advice, and periodic re-evaluation. A good first step is a formal written policy for reviewing all new and existing contracts for embedded leases, not just explicit lease agreements. This policy should clearly spell out roles and duties. For example, procurement teams identify potential contracts, legal reviews clauses, and accounting performs the ASC 842 assessment.
💡 Key Takeaway: The completeness assertion is one of the most scrutinized areas in an ASC 842 audit. Strong documentation of your contract review process is vital to show compliance.
Set up a systematic contract review workflow that sends all contracts over a materiality threshold through a central team for lease assessment. This keeps contracts from bypassing the review, which is a common pitfall. For specific guidance, see the detailed resources on lease completeness testing procedures.
Accounting teams should document their conclusions for each contract. They should detail the reasons an embedded lease does or does not exist. This record becomes key audit evidence.
To validate, consider a look-back review of a sample of contracts signed over the last 12-24 months that were not first identified as leases. This can uncover past misses and help improve current processes. A "fresh eyes" review by third-party specialists can also give an independent check on your method.
Contract abstraction and analysis tools help here. They put the clauses that matter in one place for the reviewer: asset specificity, substitution rights, configuration rights, and termination penalties. That beats hunting for them across a 60-page services agreement. For more validation steps, see our detailed guidance on lease documentation requirements.
Calculation Example: Lease vs. Service Component Allocation
Scenario: A company signs a 3-year "IT Infrastructure as a Service" contract for $1,000,000 annually. It includes dedicated server usage and managed services. The standalone price for similar dedicated servers (lease component) is $700,000 annually. The standalone price for similar managed services (service component) is $400,000 annually.
| Component | Standalone Price | Allocation Basis |
|---|---|---|
| Lease (Servers) | $700,000 | ($700,000 / $1,100,000) * $1,000,000 = $636,364 |
| Service | $400,000 | ($400,000 / $1,100,000) * $1,000,000 = $363,636 |
| Total | $1,100,000 | $1,000,000 |
The $636,364 is the annual lease payment, not the liability. At commencement the lease liability is the present value of the unpaid lease payments over the three-year term (ASC 842-20-30-1). Discount them at the rate implicit in the lease if it is readily determinable, and otherwise at your incremental borrowing rate. A lessee that is not a public business entity may instead elect a risk-free discount rate, by class of underlying asset (ASC 842-20-30-3).
Key Takeaway: Even where a contract is priced as a bundle, a lessee that separates the components allocates the consideration on a relative standalone price basis (ASC 842-10-15-33). Use observable standalone prices where they exist, and estimate them where they do not, maximizing observable information.
A lessee may instead elect, by class of underlying asset, the practical expedient not to separate non-lease components from the lease component they relate to (ASC 842-10-15-37). Elect it here and the whole $1,000,000 a year becomes lease payments. That inflates the lease liability and can flip the classification test, so it is a policy choice worth making deliberately.
Common Errors in Reviewing IT Contracts
Failing to properly identify and account for embedded leases in IT and software contracts is a common source of audit adjustments. Many organizations stumble here because they lack understanding or have weak processes. It happens time and again.
| Common Mistake | How to Avoid It (Best Practice) |
|---|---|
| Focusing only on explicit "lease" contracts. | Implement a policy to review all vendor contracts, especially service agreements, for embedded leases. |
| Assuming "services" contracts never contain leases. | Educate procurement and IT teams about the ASC 842 definition of a lease (ASC 842-10-15-3) and its potential application to IT agreements. |
| Lack of cross-functional collaboration. | Establish a formal process involving IT, legal, procurement, and accounting in contract review. |
| Absence of a clear materiality threshold for review. | Define a materiality threshold (e.g., contracts over $X, or terms over Y years) that triggers an embedded lease review. |
| Inadequate documentation of lease assessment conclusions. | Create a standardized template for documenting the lease assessment for each relevant contract, whether it's a lease or not. |
| Testing only the supplier's practical ability to substitute. | Test both limbs of ASC 842-10-15-10: practical ability and economic benefit. If the supplier can swap the server but gains nothing by swapping it, the right is not substantive and you have an identified asset. |
🚨 Critical: Failing to identify embedded leases in IT and software contracts can result in a material misstatement of the financial statements. It can also lead to audit qualifications. Auditors often find that these gaps include omitted ROU assets and liabilities, wrong lease classifications, and inadequate disclosures.
Another common mistake is not reviewing contracts on an ongoing basis. Companies sign new contracts all the time and often modify existing ones. Without a structured, ongoing review process, a team can easily miss new embedded leases.
This ties directly to why a strong system of internal controls matters. It matters most for making sure that controls over embedded leases in IT and software contracts are adequately designed and operating effectively.
The completeness assertion refers to an auditor's objective to verify that all transactions and accounts that should be recorded have been included in the financial statements. When a company misclassifies IT or software contracts and does not identify embedded leases, it inflates service expenses and deflates balance sheet assets and liabilities.
What a Thorough Software Contract Review Looks Like
Organizations that manage embedded leases in IT and software contracts well share several key traits. They take a proactive approach to lease accounting compliance. They build it into daily operations rather than treat it as an annual audit exercise. This usually starts with a strong internal control environment focused on lease identification.
✅ Best Practice: Companies that execute well often use specialized lease accounting software. It lets them centralize contract data, automate lease assessments, and manage ongoing accounting, including modifications and recalculations.
A well-run process includes a dedicated workflow for all new or amended IT and software contracts. The workflow automatically routes each one to a trained accounting professional for an ASC 842 assessment, working with IT and legal teams. This way, the team checks contracts for cloud infrastructure, dedicated servers, or specific network hardware for embedded leases up front.
Records are kept with care. They show each contract review, the reasons for lease conclusions, and any supporting calculations. This level of detail makes the audit much smoother and reduces auditor questions.
In the end, strong execution means fewer audit findings and a cleaner audit opinion related to leases. It also means accurate financial reporting that reflects the true economic substance of technology agreements.
One example of strong execution is a company that has mapped its entire IT infrastructure spending and categorized vendor types. It has also assessed potential embedded lease risks for each category ahead of time. This lets the company focus its detailed contract review where risk is highest.
Where to Go From Here on IT and Software Contracts
To improve your organization's compliance with ASC 842 for IT and software contracts, begin with a full review of your existing contract population. Develop and put in place a formal policy for identifying embedded leases in all new technology agreements. Consider using technology tools to streamline contract management and lease assessment. This often makes a large difference.
Related Articles
- Implementing Top 10 Lease Accounting Internal Controls to Ensure Success
- Auditing ASC 842 Lease Accounting: An Auditor's Guide
- New Lease Accounting Standard Implementation Challenges
Sources and further reading
Deloitte, Heads Up - Frequently Asked Questions About the FASB's New Leases Standard (April 25, 2017) - Deloitte Heads Up: FAQs about the FASB's new leases standard ↩
Deloitte, Guide for Management - Next Steps After Identifying a Deficiency in Internal Control Over Financial Reporting (October 2024) - Deloitte guide to internal control deficiencies ↩


